5 ms·
I've cracked* just under 99% of them so far (including the 14 million added in Update 1). Statistics are here: https://gist.github.com/roycewilliams/b1de2afbfe
by royce 9y ago
I've cracked* just under 99% of them so far (including the 14 million added in Update 1). Statistics are here:
https://gist.github.com/roycewilliams/b1de2afbfe5cb71bea16c94042b9bbfc https://gist.github.com/roycewilliams/b1de2afbfe5cb71bea16c9...
Regardless of composition, the top 12 lengths are:
8: 32% (102260862)
10: 14% (45084047)
9: 13% (41525797)
7: 10% (33632055)
6: 06% (20211176)
11: 05% (18275968)
12: 04% (14052958)
15: 02% (8291459)
13: 02% (8042452)
14: 01% (6321198)
16: 01% (4201765)
5: 00% (3054291)
In other words, requiring a minimum length of 12 would make 80% of the passwords in the corpus inapplicable.
... and the top 12 masks are:
?l?l?l?l?l?l?l?l,47823614
?l?l?l?l?l?l?d?d,7005728
?d?d?d?d?d?d?d?d,6212778
?l?l?l?l?l?l?l?l?l?l,6023602
?l?l?l?l?l?l?l?l?l,5379482
?l?l?l?l?l?l?l?d?d,5169013
?l?l?l?l?l?l?l?l?d?d,5090400
?l?l?l?l?l?l?l,4998896
?d?d?d?d?d?d?d,4798329
?l?l?l?l?d?d?d?d,4798124
?d?d?d?d?d?d?d?d?d?d,4754401
?l?l?l?l?l?l?d?d?d?d,4377841
Almost 48 million of them are 8 lower-case characters.
* And to be clear, "cracked" is an overstatement. Many of his sources are public. Simply using those sources as wordlists makes "cracking" these like shooting fish in a barrel.
- deleted 9y ago[deleted]
- Deimorz 9y agoOh, very cool, thanks for posting. I had actually written a really basic cracker and started seeing if I could figure out how many of them belonged to shorter passwords, but you're doing a much, much better job of it than I am (I was just brute-force generating short passwords, no wordlists or anything). Are you planning to make a blog post or anything "final" with the info you find out, or will you just keep updating those gists?
- royce 9y agoYou're welcome! And "¿por que no los dos?" :) I'll keep the gists updated and will also do a blog post, I think. With a tool like hashcat, a modern GPU or two, and some publicly available wordlists, you can get the vast majority of them without breaking a sweat. In other words: there is almost no value in hashing them with SHA1.